zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the ZYPP_LOCKFILE_ROOT environment variable.
2013-12-02T04:36:26.570
2025-04-11T00:51:21.963
Deferred
CVSSv2: 4.4 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | opensuse | zypper | ≤ 1.2.8 | Yes |
Application | opensuse | zypper | 0.11.6 | Yes |
Application | opensuse | zypper | 1.0.2 | Yes |
Application | opensuse | zypper | 1.6.16 | Yes |